Last materially reviewed: September 2, 2026
Direct Answer: Posting another person’s personal information online without permission can potentially violate Philippine privacy law, but it is not automatically illegal in every situation. The legal result depends on what information was posted, who disclosed it, how the information was obtained, the purpose of the disclosure, whether a lawful basis exists, whether the information is sensitive, and whether other rights such as freedom of expression or legitimate public interest apply. The National Privacy Commission (NPC) warned in May 2026 that unauthorized access, use, disclosure, sharing, or further dissemination of another person’s personal data may give rise to civil, administrative, or criminal liability.
Primary authority: Republic Act No. 10173 — Data Privacy Act of 2012 and the NPC notice on unauthorized access, use, disclosure and dissemination of personal data.
Key Takeaways
- Posting personal information online without consent can create liability under the Data Privacy Act of 2012 and other laws.
- Consent is important, but lack of consent does not automatically make every disclosure unlawful; another lawful basis may sometimes apply.
- Posting private addresses, phone numbers, IDs, medical information, account details, or data obtained from a breach presents much higher privacy risk.
- Reposting leaked databases, screenshots, files, or links can create additional legal exposure.
- Information that is publicly available does not automatically become free for unlimited reuse, profiling, harassment, or republication.
- If your information is posted, preserve the original evidence before requesting removal.
- You may contact the platform, the person or organization responsible, and where appropriate the National Privacy Commission.
Jump to a Section
- Is it illegal to post someone’s information online?
- Examples of risky disclosures
- What about doxxing?
- Can screenshots be posted?
- What if the information is already public?
- What if the data came from a leak or hack?
- What should you do if your data is posted?
- What evidence should you preserve?
- FAQs
Decision Snapshot
| Situation | Privacy Risk | Practical View |
|---|---|---|
| Posting someone’s home address to encourage harassment | High | May involve unlawful disclosure, harassment, or other legal issues. |
| Posting a photo of someone’s government ID | Very high | Government-issued identifying information can be sensitive personal information. |
| Sharing a customer’s phone number publicly | High | May be an unauthorized disclosure depending on circumstances. |
| Reposting a leaked database | Very high | NPC has expressly warned against reposting data obtained through unauthorized access. |
| Sharing public information for a legitimate news report | Context-dependent | Privacy, expression, public interest, and other legal rules must be balanced. |
| Posting a screenshot of a private chat | Context-dependent | May expose personal data and raise privacy or other legal concerns. |
Is It Illegal to Post Someone’s Personal Information Online Without Permission?
It can be, but the answer depends on the facts. The Data Privacy Act of 2012 (Republic Act No. 10173) regulates the processing of personal information, and disclosure is one form of processing. The law also contains criminal provisions for malicious disclosure and unauthorized disclosure in specified circumstances.
However, Philippine privacy law does not reduce every case to a simple rule that says “no consent = automatically illegal.” Some processing may be supported by another lawful basis. The type of person making the disclosure also matters because particular criminal provisions, including Section 32 on unauthorized disclosure, expressly apply to personal information controllers, processors, and their officials, employees, or agents.
For a broader explanation of what may constitute a violation, see What Counts as a Data Privacy Violation in the Philippines?
Examples of Personal Information That Can Create Serious Risk When Posted
Examples include:
- home address;
- mobile or telephone number;
- personal email address;
- government-issued ID numbers;
- photos of passports, driver’s licenses, SSS, tax, or similar records;
- bank or payment details;
- customer records;
- employee files;
- medical or health information;
- school records;
- private photographs or videos;
- transaction details;
- location information;
- screenshots containing account information;
- private messages that identify a person; and
- data copied from leaked or hacked databases.
The exact classification depends on context. Some of these may be ordinary personal information, while others can qualify as sensitive personal information.
What About Doxxing?
Doxxing generally refers to publishing identifying or private information about someone online, often to expose, intimidate, embarrass, target, or facilitate harassment against that person.
Philippine law does not treat every act commonly called “doxxing” as one single offense with one universal legal test. Depending on the facts, the conduct may involve the Data Privacy Act, cybercrime-related laws, harassment, threats, defamation, or other legal rules.
From a privacy perspective, the risk increases when a person posts data that was not meant for public distribution, uses information for an unauthorized purpose, combines separate data points to identify or target someone, or encourages others to contact, threaten, or harass the person.
Can Someone Post Your Address or Phone Number?
Potentially, but doing so can create serious privacy risk. A home address or phone number can be personal information where it identifies or relates to a particular person. Posting it publicly may constitute disclosure and can be especially problematic if there is no valid purpose or lawful basis, or if the posting is intended to expose the person to harassment, fraud, or danger.
The fact that a telephone number or address appeared somewhere previously does not automatically mean anyone may republish it for any purpose.
Can Someone Post a Photo of Your ID?
This is particularly risky. Certain government-issued information peculiar to an individual falls within the statutory definition of sensitive personal information. Posting an ID can expose a combination of name, photograph, birth date, address, signature, ID number, or other identifiers and can increase the risk of fraud and identity misuse.
Businesses should avoid publicly displaying IDs or documents containing unnecessary personal data and should use secure redaction when publication is genuinely necessary.
Can Someone Post Screenshots of Private Messages?
It depends. A screenshot can contain personal information even if the screenshot itself is only an image. Names, usernames, phone numbers, profile photos, email addresses, medical details, financial information, workplace information, and other identifying data can all appear inside screenshots.
Posting a screenshot may therefore involve privacy issues in addition to possible questions involving confidentiality, defamation, evidence, contractual duties, or other laws.
A screenshot used to document misconduct to an appropriate authority is very different from a screenshot publicly posted to expose private information to thousands of people. Purpose, audience, necessity, proportionality, and the information involved all matter.
What If the Information Is Already Public?
Public availability does not automatically create unlimited permission for reuse. A person may publish certain information on a social profile for one context, but that does not necessarily authorize another party to scrape it, combine it with other records, republish it for harassment, or use it for an unrelated commercial purpose.
The DPA Implementing Rules recognize that erasure or blocking may be relevant where private information prejudicial to the data subject is involved, while also recognizing possible justification based on freedom of speech, expression, the press, or other lawful authorization. This means context and competing rights matter.
What If the Information Came From a Data Leak, Hack, or Unauthorized Access?
Do not assume that leaked information becomes lawful to repost simply because it is already circulating online.
On May 22, 2026, the National Privacy Commission warned the public against viewing, downloading, posting, sharing, or further disseminating files, databases, screenshots, or links purported or implied to have been obtained through unauthorized access. The NPC stated that unauthorized access, use, disclosure, sharing, or further dissemination of another person’s personal data may give rise to civil, administrative, or criminal liability.
This is especially important for leaked employee databases, customer lists, government records, account dumps, private messages, medical records, or hacked cloud files.
Can an Employee Post Customer or Company Records Online?
That can create significant liability. Employees and agents who obtain personal information through their work do not generally receive unrestricted authority to disclose it publicly. Sections 31 and 32 of RA 10173 specifically address malicious and unauthorized disclosure by personal information controllers, processors, and their officials, employees, or agents.
Organizations should restrict access to personal data, train employees on confidentiality, and maintain clear incident and disclosure procedures. For the distinction between the organizations involved, see Personal Information Controller vs Personal Information Processor.
Does Consent Make Every Posting Legal?
No. Consent should be specific and tied to a legitimate purpose. A person consenting to provide information to complete a transaction does not necessarily authorize public posting.
For example, giving a courier a delivery address does not normally mean the recipient has consented to the address being posted publicly on social media.
Is Every Online Disclosure a Criminal Offense?
No. A privacy concern, a regulatory violation, and a criminal offense are not the same thing. Criminal liability depends on whether the elements of a specific offense are satisfied.
Section 32 of RA 10173, for example, specifically addresses unauthorized disclosure by a PIC, PIP, or their officials, employees, or agents. Other situations may instead involve different provisions, administrative liability, civil claims, platform rules, or other Philippine laws.
For criminal fines and imprisonment ranges, see Penalties for Violating the Data Privacy Act in the Philippines.
What Should You Do If Someone Posts Your Personal Information?
- Preserve the evidence first. Record the post, URL, account, date, time, and surrounding context.
- Assess the immediate risk. If an address, financial information, account credentials, or identity documents were exposed, secure affected accounts and consider additional protective measures.
- Request removal where appropriate. Contact the poster or responsible organization if it is safe and practical.
- Use the platform’s reporting tools. Social networks and websites may have privacy, harassment, impersonation, or personal-information reporting mechanisms.
- Contact the organization’s Data Protection Officer. This is particularly relevant when the disclosure came from a company, employer, school, hospital, bank, platform, or other organization.
- Consider an NPC complaint. If you believe your data subject rights were violated, the National Privacy Commission provides a complaint process.
- Consider other authorities when necessary. Threats, hacking, extortion, fraud, identity theft, or other criminal conduct may require a different or additional reporting route.
For your broader privacy rights, see Data Privacy Rights in the Philippines: What Are Your Rights?
What Evidence Should You Preserve?
Preserve:
- full screenshots showing the account name and content;
- the exact URL;
- date and time;
- the poster’s username or profile URL;
- comments, shares, reposts, or messages showing distribution;
- copies of private messages related to the disclosure;
- emails or notices from the responsible organization;
- the original file, where available;
- proof of your request for removal;
- platform responses; and
- records showing harm, fraud attempts, harassment, or other consequences.
Do not unnecessarily crop, alter, overwrite, or delete the original evidence. Keep an unedited copy whenever possible.
Can You Ask for the Information to Be Deleted?
Potentially, yes. The DPA and its Implementing Rules recognize rights involving erasure or blocking in qualifying circumstances, including where processing is unlawful, data is unlawfully obtained, it is being used for an unauthorized purpose, or other applicable grounds exist.
However, deletion rights are not absolute. Legal obligations, legitimate interests, freedom of expression, evidence preservation, public interest, and other lawful grounds can affect the result.
Can You Claim Damages?
Potentially. The Data Privacy Act recognizes a right to indemnification for damage caused by specified inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized uses of personal information. Whether damages are actually recoverable depends on the facts and the applicable proceeding.
Frequently Asked Questions
Can someone post my phone number on Facebook without permission?
It can create a privacy issue because a phone number linked to you may be personal information. Whether the posting violates the law depends on the purpose, lawful basis, source of the data, who posted it, and other circumstances.
Is posting someone’s address online illegal?
It can be unlawful in some circumstances, particularly where the address is disclosed without proper authority or is used to target, threaten, harass, or expose the person to harm. The exact legal analysis depends on the facts.
Can someone post my ID online?
Posting a government ID can create serious privacy and identity-security risk. Government-issued information peculiar to an individual may constitute sensitive personal information under RA 10173.
Can I repost leaked personal data if someone else posted it first?
You should not assume so. In May 2026 the NPC specifically warned against posting, sharing, or further disseminating data and files obtained through unauthorized access.
Can screenshots violate data privacy?
Yes, potentially. Screenshots can contain personal or sensitive personal information, and public disclosure may raise privacy issues depending on context.
Is doxxing illegal in the Philippines?
There is no single universal legal rule that makes every act described as doxxing the same offense. Depending on the conduct, the Data Privacy Act and other laws may apply.
What should I do first if someone exposes my personal data?
Preserve evidence before the content disappears, assess immediate security risks, request removal where appropriate, use platform reporting tools, and consider contacting the relevant organization, its DPO, or the NPC.
Can I file a complaint with the National Privacy Commission?
Potentially, yes. A data subject who believes their privacy rights have been violated may use the NPC complaint process subject to applicable requirements.
Official Sources
- Republic Act No. 10173 — Data Privacy Act of 2012
- Implementing Rules and Regulations of RA 10173
- NPC Notice to the Public — May 22, 2026
- National Privacy Commission — Data Subject Rights
For the broader legal framework beyond online posting, see Invasion of Privacy Laws in the Philippines: What Is Illegal?
Related Cybercode Guides
- Data Privacy Act of 2012 Philippines
- Data Privacy Rights in the Philippines
- What Is Personal Information?
- What Is Sensitive Personal Information?
- What Counts as a Data Privacy Violation?
- Penalties for Violating the Data Privacy Act
Cybercode.ph provides general educational information about technology, cybersecurity, privacy, and related legal issues. It is not a substitute for legal, cybersecurity, or professional advice for a specific situation.
